PT-2026-98219 · Github · Mail-Mime-Parser
CVE-2026-61815
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
zbateson/mail-mime-parser versions prior to 3.0.6
zbateson/mail-mime-parser versions prior to 4.0.2
Description
CRLF (carriage-return / line-feed) header injection occurs when the library is used to build or forward MIME messages with an attacker-influenced attachment filename. Attachment filenames are interpolated into the
Content-Type and Content-Disposition header values without stripping CR/LF characters. This allows a filename containing r to create additional attacker-controlled header lines, such as a forged Bcc: header to silently exfiltrate copies of outgoing messages.On the outbound side, the
MultipartHelper::createAndAddPartForAttachment() function fails to strip CR and LF characters before they are written into the header via MimePart::setRawHeader(). On the decode side, ParameterPart::decodePartValue() and the MimeToken path can allow CR/LF characters to persist or be reintroduced into the value returned by getFilename(). Consequently, an application that re-attaches or re-sends a filename parsed from inbound mail is exposed.Recommendations
Update zbateson/mail-mime-parser to version 3.0.6 or later.
Update zbateson/mail-mime-parser to version 4.0.2 or later.
As a temporary workaround, strip CR and LF characters from any filename before passing it to attachment APIs and from the result of the
getFilename() function before reusing it in a constructed message.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mail-Mime-Parser